'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2012-1823,CVE-2012-2311,CVE-2012-2336: PHP-CGI Remote Code Execution Vulnerability
Severity:high
CVE ID:CVE-2012-1823 CVE-2012-2311 CVE-2012-2336
| Descripiton:
|
PHP (PHP: Hypertext Preprocessor, PHP: Hypertext Preprocessor) is an open source general-purpose computer scripting language jointly maintained by the PHP Group and the open source community. The language is mainly used for web development and supports a variety of databases and operating systems. An information disclosure vulnerability exists in PHP. A remote attacker could exploit the vulnerability to view the source code of a file in the context of a server process, obtain sensitive information, run arbitrary PHP code on the affected computer, and possibly perform other attacks. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.